← All Advisories

CVE-2026-93224

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93224

Key Details

CVECVE-2026-93224
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Fix unmatched rn_unregister on failed accept

When svc_rdma_accept() takes the errout path before

rpcrdma_rn_register() has succeeded, the existing cleanup block

calls rpcrdma_rn_unregister(dev, &newxprt->sc_rn) unconditionally.

svcxprt_rdma is kzalloc'd, so on that path sc_rn.rn_index is 0 and

sc_rn.rn_done is NULL; the unregister therefore xa_erase()s another

caller's slot 0 and performs an unmatched kref_put() on the

rpcrdma_device's rd_kref.

The same errout also brackets the cleanup with svc_xprt_get()/

svc_xprt_put() around the kref_init() birth reference. The kref

goes 1 -> 2 -> 1 and never reaches 0, so the svcxprt_rdma (and the

net/ns_tracker it pinned) is leaked on every failed accept.

rpcrdma_rn_register() writes rn->rn_done last, only after xa_alloc()

and kref_get() have both succeeded, so rn_done == NULL is a natural

"never registered" sentinel. Guard rpcrdma_rn_unregister() with an

early return when rn_done is NULL, and clear rn_done before the

matching xa_erase() so a repeated unregister is also a no-op.

With that guard in place, the accept errout drops the kref_init()

birth reference via svc_xprt_put(), which dispatches svc_rdma_free().

Teardown of sc_qp, sc_sq_cq, sc_rq_cq, and sc_pd runs under existing

IS_ERR/NULL guards in svc_rdma_free(); sc_rn is covered by the new

rn_done sentinel; sc_cm_id is non-NULL on every errout path because

svc_rdma_accept() dereferences it above the first goto errout.

svc_xprt_free() drops the module reference associated with the freed

transport, and svc_handle_xprt() drops its pre-acquired reference

when ->xpo_accept() returns NULL. Take a replacement module reference

before svc_xprt_put() so the two module_put()s remain balanced.

The rn_done guard also covers svc_rdma_free()'s non-listener call

to rpcrdma_rn_unregister() for transports whose register attempt

failed or never ran. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93224
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93224